Langgenius maintains Dify, an open-source platform for building and deploying large language model applications, which has attracted vulnerability research attention despite a narrow product footprint. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through access-control weaknesses, cross-site scripting, server-side request forgery, and origin validation errors that are characteristic of web-facing AI application frameworks where trust boundaries between user input, model inference, and external integrations demand careful enforcement. Defenders deploying or extending Dify should prioritize input validation, access control design, and network isolation for inference endpoints; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Langgenius over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63387HIGH Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authenti | Dec 18, 2025 | 7.5 | 57 | NO | YES |
CVE-2026-61461HIGH Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search par | Jul 10, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-41948CRITICAL Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by ex | May 18, 2026 | 9.4 | 39 | NO | NO |
CVE-2026-41947CRITICAL Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardle | May 18, 2026 | 9.1 | 37 | NO | NO |
CVE-2025-56157CRITICAL Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the | Dec 18, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-63388CRITICAL A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissi | Dec 18, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-63386CRITICAL A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that | Dec 18, 2025 | 9.1 | 32 | NO | NO |
CVE-2026-41949HIGH Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uplo | May 18, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-11750MEDIUM In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accoun | Oct 22, 2025 | 5.3 | 30 | NO | YES |
CVE-2026-41950MEDIUM Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same | May 5, 2026 | 6.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Langgenius.
Media articles that mention a CVE ID that affects a product developed by Langgenius — matched by CVE ID, not by vendor name.